Runtimezruntimez
runtimez / product / kubernetes-security
product · kubernetes security

See who can reach cluster-admin — and which CVE to fix first.

Attack paths, image CVEs, misconfigurations and compliance scorecards, ranked in the same queue as reliability and upgrade risk. The agent that finds them is read-only and never reads a secret value.

one helm install · get, list, watch only · first findings in minutes

18attack-path rules over RBAC, tokens and cloud identity
3compliance frameworks: CIS Kubernetes, CIS EKS, NSA
100%of running images scanned, in-cluster
0secret values read: names only

Security posture

One ranking for security and reliability.

Attack paths

Who can reach cluster-admin, node root, every Secret or a cloud role, and through which grants. 18 rules cover RBAC bindings, ServiceAccount tokens, pod escalation and cloud identity.

18 rulesRBAC

Image CVE scanning

Every running image is scanned, showing the CVE, package, fixed version and severity for each workload. The scanner runs as an ephemeral Job in your cluster.

in-clusterper workload

Misconfiguration posture

Privileged containers, running as root, hostPath mounts and missing security context add up to a posture score.

posture score

Compliance scorecards

CIS Kubernetes, CIS EKS and NSA, with pass or fail per control and the failing resources named.

CISNSA

Unified score and fleet ranking

One security number per cluster, with the fleet ordered by criticality.

fleet

Fix-first across axes

A critical CVE on the workload that also blocks your 1.31 upgrade is ranked first, because one change clears both. Rescan on demand and work from a prioritized remediation drawer.

cross-axisremediation
Runtimez workload risk: contributing security factors for a workload, from critical CVEs to seccomp and runAsUser findings
Runtimez workload risk: contributing security factors for a workload, from critical CVEs to seccomp and runAsUser findings

A security review your team will approve

The trust posture is the product.

Read-only RBAC

Only get, list and watch. No mutating verbs, no kubeconfig handover, no inbound access. Uninstall is one command.

read-only

Secret names only

The inventory records that a secret exists. Values are never read or transmitted.

no values

Scanning stays inside

Scan Jobs run as ephemeral pods in your cluster. Images and pull secrets never leave it.

no egress

Multi-tenant with roles

Everything is scoped to your org, with Owner, Admin, Platform Engineer, Developer and Viewer roles.

org-scopedRBAC roles

Redaction on every AI path

Evidence is scrubbed of secrets before it reaches any model.

redaction

Its own findings, labelled

The Runtimez agent's own attack-path findings are tagged as expected, each with the chart value that removes it.

transparent

How it compares

vs Wiz / Snyk

They rank CVEs by severity. Runtimez ranks them by which fix also unblocks your upgrade.

See it on your own cluster in under an hour.

Free for your first cluster. Read-only by default. Uninstall is one helm command.